Impact
The flaw exists in the UsersWP WordPress plugin before version 1.5.10. When a user authenticates via a social login provider, the plugin trusts the provider's claimed email address without ensuring that the provider has confirmed ownership of that address. An attacker who controls a provider account can supply the email address of any existing WordPress user, including administrators, and the plugin will map the social login to that account. Consequently, the attacker can log in as that user without authenticating to the WordPress site or the provider, which grants full control over the targeted account.
Affected Systems
The vulnerability affects installations of the UsersWP plugin for WordPress where the plugin version is older than 1.5.10. Any site running WordPress with that plugin and using social login for any user account is exposed, with administrators whose email addresses are known being at particular risk.
Risk and Exploitability
The CVSS score is not provided, so the precise severity cannot be quantified. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, suggesting no confirmed public exploitation yet. Exploitation requires the attacker to have an account on the social provider that matches the target's email address. If the attacker can forge such a provider account, they can hijack the target account because the plugin does not verify email ownership. Given that an unauthenticated attacker can gain the same privileges as the target user, the overall risk level is significant.
OpenCVE Enrichment